Netskope Threat Labs

FILE-OTHER Microsoft Excel malicious CSV code execution attempt

IPS-SWG

2 SIDs: 47260, 47262

First seen
November 2022
Last seen
October 2026

Detects spreadsheet content that launches dynamic interfaces from formula fields, a CSV injection technique. The crafted cells execute when a user opens the file in Excel, making this a social engineering delivery vector that needs no exploit.